Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date: Thu, 03 Mar 2016 09:25:30 +0800
From: Paul Wise <>
Subject: Mitre, reserved CVEs and oss-security?

Hi all,

I think it would be a good idea for Mitre to remove the RESERVED mark
from CVEs that have been released for use by people mailing issues to
the oss-security to get CVE numbers. The CVE database could then point
at the oss-security mailing list archives as a reference for the issue.

Any thoughts?

For example CVE-2016-2515 could refer to one of these posts:


Download attachment "signature.asc" of type "application/pgp-signature" (802 bytes)

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.